About Expertise Work Managed Apps
Business Website Online Store Sales CRM Team Drive Online Academy Newsletter System Booking System Shared Inbox Knowledge Base Short Links Business Manager Photo Gallery Survey Platform Community Forum Project Boards Estate Agency Car Workshop Restaurant Clinic Photography Studio
AWS
Assess & advise Build & migrate Automate & operate Secure & comply Urgent & go-live
Projects
Hosted Monitoring & Dashboards Self-Hosted Observability Stack Bulk Document Data Extraction Email Deliverability Diagnosis & Repair SEO Migration Recovery AWS Security Review VPS Hardening & ModSecurity Cloud Architecture & Resilience Review SSL & Server Configuration Container Security Review DNS & Email Troubleshooting DevOps Deployment & Rollback Review WordPress Hardening Retainer Data Pipeline Rerun Review Metric Reconciliation
Free Tools
Website Health Check Email Domain Health Check DNS Health Check SSL Certificate Checker Redirect Chain Checker Robots.txt Checker XML Sitemap Validator Docker Compose Checker WordPress Security Check AWS IAM / S3 Policy Checker Domain Registration Lookup Uptime Monitoring Trial Downtime Cost Calculator AWS Cost Estimator Cloud Architecture Self-Assessment DevOps Engagement Builder Self-Managed VPS vs Managed AWS
Blog Certifications Hire Me

Healthcare / HIPAA-Oriented AWS Infrastructure

The technical controls a HIPAA workload needs on AWS, built and documented. Not a certification.

Price and scope

From $1,149

Typically $1,149–$3,499, fixed in writing before anything starts.

7–15 days
Working days, counted from the moment I have access — not from the day you agree.

What moves it up

  • Retrofitting a production system that already holds data, rather than building clean
  • Several services in scope, each needing its own encryption, logging and access decision
  • An auditor or a customer security review already scheduled, which sets the evidence standard
What the BAA actually coversAn architecture spanning the boundary of AWS HIPAA eligible services. Four services sit inside the boundary the Business Associate Addendum covers. A fifth holds the same data and is not on the eligible list.HIPAA ELIGIBLE · COVERED BY THE BAAEC2RDSS3KMSsigning the BAA permits PHI hereNOT ON THE LISTa serviceholding the same datanothing in the consolewarns you about thisPHI leaves the boundary
Healthcare / HIPAA-Oriented AWS Infrastructure

What actually goes wrong

The Business Associate Addendum gets signed and people relax, because AWS is now "HIPAA compliant". What the BAA actually does is permit protected health information on a defined list of eligible services — it makes nothing compliant on its own, and using an ineligible service puts you outside it without any warning from the console. Underneath that, the controls that fail a review are always the same ones: encryption in transit between internal services rather than only at the edge, an audit trail of who accessed a record rather than who changed infrastructure, and backups that are encrypted but not access-controlled separately from production.

How I find it

  • Every service in the architecture checked against the current AWS HIPAA eligible services list
  • aws kms list-keys and describe-key — customer-managed keys with rotation, or the AWS-managed default
  • aws rds describe-db-instances --query 'DBInstances[].[StorageEncrypted,PubliclyAccessible]'
  • Application-level access logging, which is where record-level access lives and infrastructure logs do not reach

What you get

  • Encryption at rest with customer-managed keys, and in transit between internal services as well as at the edge
  • Private networking, with no protected data path traversing the public internet
  • Audit logging that answers who accessed which record, delivered somewhere production cannot alter
  • Backups encrypted, access-controlled separately, and restored once to prove it
  • A written control mapping — each HIPAA technical safeguard against what implements it and where the evidence lives

Questions

Does this make me HIPAA compliant?

No, and be careful with anyone who says otherwise. HIPAA compliance covers policies, training, agreements and risk assessments as well as technology. This builds and documents the technical safeguards, which is a substantial part of it and not the whole. I am an engineer, not your compliance officer or your lawyer.

Do I need a BAA with AWS, and does that cover me?

You need one, it is free, and you accept it in Artifact. It permits protected health information on AWS's list of eligible services. It does not make your architecture compliant, and nothing stops you using an ineligible service after signing it — which is one of the first things this engagement checks.

Can you retrofit this onto a system already holding patient data?

Yes, and it is the normal case. It costs more than building clean because some changes — encrypting an unencrypted database, moving a subnet — require a maintenance window and a migration rather than a setting. Those are identified and scheduled rather than discovered halfway.

Will this satisfy our customer's security questionnaire?

The technical sections, largely — that is what the control mapping is for, so each answer points at something real rather than a claim. Questions about your policies, your staff training and your incident process are yours to answer, and no infrastructure work will do it for you.

Want this done?

Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.

Prefer to talk? Book a free call ↗  ·  Or hire me on Upwork ↗  ·  Typical reply within one business day.

When I answer

Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.

No 24/7 desk, and I will not pretend otherwise

One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.

Your AWS bill stays yours

You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.

A price that starts with "from" is a starting price

Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.